Key developments
ICE shared Medicaid data with Palantir
WLRN's Jude Joffe-Block reports that new court filings show ICE shared improperly obtained Medicaid data with Palantir after CMS transferred data on millions of people in January. The data was connected to Palantir's ELITE application, used by ICE agents to display addresses of noncitizens potentially subject to deportation. Justice Department filings said ICE deleted one reshared file but later found copies with approximately six users, while Democratic attorneys general argued the repeated violations undermine assurances that Medicaid data remains private.
Why it matters
The filings put sensitive health-program data directly inside immigration-enforcement infrastructure and raise unresolved questions about whether the government can reliably delete improperly shared records.
Sources & driving stories
WLRN · Jude Joffe-Block
WLRN coverageHouse bill targets federal surveillance access
The New American's Michael Tennant reports that Rep. Keith Self introduced the Protecting Rights in Video and Equipment Acquired Discovery Act, cosponsored by Reps. Eli Crane and Andrew Clyde. The bill would require warrants before federal law-enforcement agencies access data from state or local mass-surveillance systems, including automated license-plate readers, surveillance cameras such as Flock deployments, and long-range microphones. It would also impose a 30-day retention limit for lawfully obtained covered data, restrict federal funding for covered devices, and bar use of such data to track people solely based on First Amendment activity.
Why it matters
The proposal directly targets a growing federal-local surveillance data pipeline that has drawn privacy objections over warrantless movement tracking and cross-agency sharing.
Sources & driving stories
THE NEW AMERICAN · Michael Tennant
The New American coverageEY discloses third-party tax document breach
GBHackers' Eswar reports that Ernst & Young LLP confirmed attackers accessed a third-party IT service-management platform used by its tax practice and downloaded support-ticket attachments. EY detected anomalous activity on April 23 and found unauthorized access occurred from March 28 to April 12; California breach notifications were filed July 15 and individual notices were dated July 13. The exposed materials included personal details tied to investment holdings and financial information used in or contained within tax filings, with possible categories including Social Security numbers and tax-preparation data.
Why it matters
Support-ticket systems can accumulate highly sensitive client documents while sitting outside core financial systems, making third-party platforms a significant privacy and breach-notification risk.
Sources & driving stories
GBHACKERS · Eswar
GBHackers coverageWorth noting
WORTH NOTING
Frontier faces two breach lawsuits
View from the Wing's Gary Leff reports two proposed class actions after a breach affecting 11,482 employees and customers, with Texas records listing unauthorized access from May 12 to June 3 and exposed data including Social Security and government ID numbers.
WORTH NOTING
Ecopetrol reports account data theft
Yahoo Finance reports Colombia's Ecopetrol said a cyberattack stole data tied to about 3,300 accounts across cloud file-storage environments at 15 subsidiaries, while the company said it prevented an attempted ransomware attack and saw no production disruption.
WORTH NOTING
23andMe settlement announced by AGs
ABC Columbia reports South Carolina Attorney General Alan Wilson announced a 42-state settlement over the 2023 23andMe genetic data breach, resolving allegations tied to nearly seven million compromised customers through $150 million in allowed claims.
Still unclear
OPEN QUESTION
Can ICE prove Medicaid data deletion?
The court filings describe lingering copies and technical difficulty locating file variants, which will matter if the Justice Department seeks broader access to noncitizen Medicaid data.
OPEN QUESTION
Will surveillance warrant rules converge?
Congressional warrant proposals, Flock litigation, and recent location-data rulings are all pressing the same question: when aggregated public-space tracking becomes a Fourth Amendment search.
